web-app-logic

Map web application logic vulnerabilities to actionable test scenarios.

3|1|Updated May 26, 2026
One-click install
npx skills add https://github.com/LeoWSY-hashblue/-communitytools-custom --skill web-app-logic-leowsy-hashblue
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: web-app-logic
Source: https://github.com/LeoWSY-hashblue/-communitytools-custom/tree/main/skills/web-app-logic
Command: npx skills add https://github.com/LeoWSY-hashblue/-communitytools-custom --skill web-app-logic-leowsy-hashblue

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Web App Logic Testing helps security teams quickly identify and exploit common logic flaws in web applications.

Core Features & Use Cases

  • Comprehensive coverage of business logic, access control, race conditions, and cache deception.
  • Provides end-to-end workflows from discovery to PoC to reporting.
  • Use cases include IDOR, parameter pollution, multi-step bypass, and information leakage scenarios.

Quick Start

Describe the target web application and request a starter PoC to test business logic, access control, and information-disclosure scenarios.

Frequently Asked Questions about web-app-logic

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find business logic flaws in a web application?

To find business logic flaws, this skill maps web application logic vulnerabilities to actionable test scenarios, covering access control, multi-step bypass, and parameter pollution from discovery to reporting.

What is the best way to test for IDOR and information disclosure vulnerabilities?

Testing for IDOR and information disclosure involves structured discovery and repeatable testing guidance. This skill provides end-to-end workflows to safely evaluate these access control and leakage scenarios.

How can I safely detect race conditions and web cache poisoning?

You can safely detect race conditions and cache deception by requesting a starter proof of concept. The skill enforces structured discovery with safety checks before evaluating these logic vulnerabilities.

Can I generate a PoC for web application access control bypasses?

Yes, you can generate a starter PoC for web application access control bypasses. Describe the target web application to receive actionable test scenarios for multi-step bypass and IDOR evaluation.

Does web logic testing require specific frameworks or dependencies?

Web logic testing using this skill requires no specific dependencies or external components. You only need to describe the target web application to begin the AI-assisted evaluation of logic flaws.

What is included in the workflow for reporting web security logic flaws?

The reporting workflow for web security logic flaws includes reconnaissance, reference material curation, proof of concept generation, and clearly defined outcomes to map vulnerabilities to actionable test scenarios.